1Password: a password manager worth recommending1password.com
After using 1Password Teams for several years, I finally moved my personal password vault to them as well. The UX and support are an order of magnitude better than where I came from.
After using 1Password Teams for several years, I finally moved my personal password vault to them as well. The UX and support are an order of magnitude better than where I came from.
It's in iOS 12.1.4, which also fixes two zero-days that are actively being exploited. The FaceTime bug is also fixed in MacOS. Update 'em if you got 'em.
To try and keep the crypto assets secure, only the founder had the password for the cold storage. About $190 million is now stuck in limbo.
This would be a great anti-phishing feature. It's currently being experimented with in the Canary build of Chrome 74.
More good browser news. Although this kinda falls into the category of "how was this not a thing yet?".
If you're running Android you might want to install the February security updates asap. There's an exploit where simply opening a malicious .png file can compromise you. There's no attacks seen yet, but I can't image it'll take long.
A malicious app, even without admin privileges, can get access to passwords stored inside Keychain. However, the security researcher refuses to share details of the exploit with Apple because they don't provide a bug bounty program for MacOS.
I keep pronouncing it "Adamantium", and now you will too. Seriously Google, if you're naming security things, why not go with Wolverine nomenclature instead of with what's apparently a type of fern.
Anyway. The fern allows lower-end Android devices to also start using device encryption. They currently can't because they don't have the computing power or hardware support for it.
It will warn you when you log into a site with credentials that are known to be leaked. They say it does this without revealing personal details to Google.
It's been known for a while that Gmail's "dot addresses" feature leads to some interesting attacks, like Netflix phishing where you're asked to update someone else's credit card info. This post shows a few more uses that have been seen, like submitting credit card applications and filing false tax returns.
The headline sounds a bit sensationalist, but it's an interesting read and a very unfortunate example of how not to react to vulnerability disclosure.
One slot is taken by the amazing 1Password, but the other is currently available. If your company wants to support this newsletter and reach nearly 4000 security-minded people, hit reply and let me know :-)